CVE-2026-34160
- EPSS 0.34%
- Veröffentlicht 14.04.2026 21:09:36
- Zuletzt bearbeitet 24.07.2026 22:10:00
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, the PENS (Package Exchange Notification Services) plugin endpoint at public/plugin/Pens/pens.php is accessible without authentication and accepts a user-contro...
CVE-2026-33715
- EPSS 0.21%
- Veröffentlicht 14.04.2026 21:05:35
- Zuletzt bearbeitet 24.07.2026 23:10:00
Chamilo LMS is an open-source learning management system. In version 2.0-RC.2, the file public/main/inc/ajax/install.ajax.php is accessible without authentication on fully installed instances because, unlike other AJAX endpoints, it does not include ...
CVE-2026-33714
- EPSS 0.26%
- Veröffentlicht 14.04.2026 21:00:19
- Zuletzt bearbeitet 24.07.2026 23:10:00
Chamilo is an open-source learning management system (LMS). Version 2.0.0-RC.2 contains a SQL Injection vulnerability in the statistics AJAX endpoint, which is an incomplete fix for CVE-2026-30881. While CVE-2026-30881 was patched by applying Securit...
CVE-2026-33708
- EPSS 0.21%
- Veröffentlicht 10.04.2026 19:16:24
- Zuletzt bearbeitet 16.04.2026 18:25:15
Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any authenticated user, including stud...
CVE-2026-33710
- EPSS 0.29%
- Veröffentlicht 10.04.2026 19:16:24
- Zuletzt bearbeitet 16.04.2026 18:24:17
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, REST API keys are generated using md5(time() + (user_id * 5) - rand(10000, 10000)). The rand(10000, 10000) call always returns exactly 10000 (min == max), making the formul...
CVE-2026-33736
- EPSS 0.21%
- Veröffentlicht 10.04.2026 19:16:24
- Zuletzt bearbeitet 16.04.2026 18:23:31
Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, any authenticated user (including ROLE_STUDENT) can enumerate all platform users and access personal information (email, phone, roles) via GET /api/users, including administrator accou...
CVE-2026-33737
- EPSS 0.22%
- Veröffentlicht 10.04.2026 19:16:24
- Zuletzt bearbeitet 16.04.2026 18:22:09
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerability is fixed in 1.11.38 and 2....
CVE-2026-33706
- EPSS 0.17%
- Veröffentlicht 10.04.2026 19:16:23
- Zuletzt bearbeitet 16.04.2026 18:27:48
Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user with a REST API key can modify their own status field via the update_user_from_username endpoint. A student (status=5) can change their status to Teacher/CourseMana...
CVE-2026-33707
- EPSS 0.43%
- Veröffentlicht 10.04.2026 19:16:23
- Zuletzt bearbeitet 16.04.2026 18:25:38
Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, the default password reset mechanism generates tokens using sha1($email) with no random component, no expiration, and no rate limiting. An attacker who knows a user's email...
CVE-2026-33705
- EPSS 0.25%
- Veröffentlicht 10.04.2026 18:32:45
- Zuletzt bearbeitet 16.04.2026 18:29:46
Chamilo LMS is a learning management system. Prior to 1.11.38, Twig template files (.tpl) under /main/template/default/ are directly accessible without authentication via HTTP GET requests. These templates expose internal application logic, variable ...